7.5

CVSS3.1

CVE-2025-22364 - WordPress Ach Invoice App plugin <= 1.0.1 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Service Shogun Ach Invoice App ach-invoice-app allows PHP Local File Inclusion.This issue affects Ach Invoice App: from n/a through <= 1.0.1.

πŸ“… Published: Jan. 7, 2025, 10:48 a.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

6.4

CVSS3.1

CVE-2024-12699 - Service Box <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Service Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary we…

πŸ“… Published: Jan. 7, 2025, 9:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-12152 - MIPL WC Multisite Sync <= 1.1.5 - Unauthenticated Arbitrary File Download

The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.5 via the 'mipl_wc_sync_download_log' action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain …

πŸ“… Published: Jan. 7, 2025, 9:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-12719 - WordPress File Upload <= 4.24.15 - Missing Authorization to Authenticated (Subscriber+) Limited Pat…

The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wfu_ajax_action_read_subfolders' function in all versions up to, and including, 4.24.15. This makes it possible for authenticated attackers, with Subscriber-level ac…

πŸ“… Published: Jan. 7, 2025, 9:22 a.m. πŸ”„ Last Modified: April 8, 2026, 4:45 p.m.

4.4

CVSS3.1

CVE-2024-54030 - Communication_dsoftbus has an UAF vulnerability

in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOSΒ through use after free.

πŸ“… Published: Jan. 7, 2025, 7:57 a.m. πŸ”„ Last Modified: Oct. 16, 2025, 3:11 p.m.

8.8

CVSS3.1

CVE-2024-47398 - Liteos_a has an out-of-bounds write vulnerability

in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the device is unable to boot up through out-of-bounds write.

πŸ“… Published: Jan. 7, 2025, 7:57 a.m. πŸ”„ Last Modified: Oct. 16, 2025, 3:09 p.m.

5.5

CVSS3.1

CVE-2024-45070 - Liteos_a has an out-of-bounds read vulnerability

in OpenHarmony v4.1.2 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

πŸ“… Published: Jan. 7, 2025, 7:56 a.m. πŸ”„ Last Modified: Oct. 16, 2025, 3:09 p.m.

6.8

CVSS3.1

CVE-2024-11627 -

: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327,Β from 15.2.8400 through 15.2.8421.

πŸ“… Published: Jan. 7, 2025, 7:49 a.m. πŸ”„ Last Modified: July 29, 2025, 7:33 p.m.

8.4

CVSS3.1

CVE-2024-11626 -

Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15…

πŸ“… Published: Jan. 7, 2025, 7:49 a.m. πŸ”„ Last Modified: July 29, 2025, 7:34 p.m.

7.7

CVSS3.1

CVE-2024-11625 -

Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.

πŸ“… Published: Jan. 7, 2025, 7:48 a.m. πŸ”„ Last Modified: July 29, 2025, 7:35 p.m.
Total resulsts: 349182
Page 7256 of 34,919
Β« previous page Β» next page
Filters